Cybersecurity
Curated coverage and analysis in this editorial area.

CVE-2026-40400: RCE in PowerShell via Help File, Patch Available
ZDI-26-414 discloses a directory traversal flaw in PowerShell help file parsing that leads to remote code execution with user interact…

Cisco ISE Authenticated Directory Traversal (CVE-2026-20146) Exposes System Files
A directory traversal flaw in Cisco Identity Services Engine lets authenticated attackers read sensitive files. The vulnerability, rat…

Adobe Creative Cloud Update Service Turned Into Privilege Escalation Weapon
ZDI-26-419 reveals a vulnerability in AdobeUpdateService that allows local privilege escalation from low-privilege user to SYSTEM on W…

Synology DS925+: Pre-Auth Root RCE via Weak Redis Passwords — Patch Available
ZDI-26-423 discloses a pre-authentication vulnerability in the MailPlus Redis component of the Synology DiskStation DS925+. Reversible…

NVIDIA NeMo Framework: RCE Vulnerability in ML Checkpoints
An unsafe deserialization flaw in NVIDIA NeMo Framework checkpoints enables remote code execution. User interaction is required, but t…

7-Zip XZ Parser RCE Vulnerability: Opening an Archive Is Enough
A heap-based buffer overflow in 7-Zip's XZ parser enables remote code execution. The flaw, tracked as ZDI-26-444 and CVE-2026-14266, t…

SAP Patches CVSS 9.9 ABAP Kernel Bug: Mandatory Downtime or SAP GUI for HTML Breaks
CVE-2026-44747 is an out-of-bounds write in the SAP NetWeaver ABAP kernel with total impact on confidentiality, integrity, and availab…

SonicWall SMA 1000: Two Actively Exploited Zero-Days and a Patch That Isn't Enough
SonicWall patched two zero-days under active exploitation in SMA 1000 Series appliances, but the vendor mandates full re-imaging or re…

FortiBleed: 75,000 Firewalls at Risk from Stolen Credentials, Not a Zero-Day
FortiBleed hits already-patched FortiGate devices: credentials stolen in prior incidents enable administrative access without exploiti…

Security Vendor Jscrambler Becomes Supply-Chain Vector: 5 Malicious npm Versions
Threat actors compromised Jscrambler's npm publishing credentials and released five malicious versions of the jscrambler package conta…

ZDI Publishes 0-Day in Glary Utilities: LPE via Junction, No Patch
Trend Micro's Zero Day Initiative has disclosed ZDI-26-402, a local privilege escalation vulnerability in Glarysoft Glary Utilities. T…

Zimbra Patches Critical Stored XSS in Classic Web Client, Reported by Google TAG
Zimbra released ZCS 10.1.19 on July 7, 2026 to fix a stored cross-site scripting vulnerability in the Classic Web Client reported by G…